> Markdown version of [/jobs/ext/2610437-application-security-manager](https://www.wearedevelopers.com/jobs/ext/2610437-application-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Manager - **Company:** Bed Bath & Beyond Inc. - **Location:** Center, TX, United States - **Salary:** $150,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Applications Architecture, Application Firewall, Microsoft Azure, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Information Systems, Continuous Integration, DevOps, Fraud Prevention and Detection, Python (Programming Language), Node.Js, Systems Development Life Cycle, Reliability Engineering, Cloud Services, Secure Coding, Web Application Security, TypeScript, Software Vulnerability Management, Web Applications, Data Logging, Google Cloud, Delivery Pipeline, Software Security, GWAPT, Containerization, Git Flow, Information Technology, Oracle Cloud Infrastructure, Devsecops, Api Management, Static Application Security Testing, BIG‑IP Application Security Manager (ASM), Dynamic Application Security Testing - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c8aea8f90798e1aa ## About the Role * Hands-on experience with application security assessments, secure code reviews, threat modeling, API testing, security design reviews, and risk-based remediation. * Experience leading or materially coordinating application security, secure SDLC, vulnerability governance, DevSecOps, vulnerability disclosure, bug bounty, external testing, or coordinated vulnerability intake processes. * Experience with SAST, DAST, SCA, secrets detection, container scanning, cloud security posture, WAF or runtime protection, and vulnerability management tooling. * Working knowledge of application architectures, APIs, authentication and authorization patterns, CI/CD pipelines, dependency management, Git-based workflows, and cloud-hosted delivery models. * Ability to partner with engineers, architects, platform teams, product leaders, and security teams to drive practical remediation, control adoption, and business-appropriate security decisions. * Ability to create clear metrics, dashboards, technical documentation, remediation guidance, project plans, executive summaries, and leadership-ready risk reporting. * Proficiency in at least one common development or scripting language such as Java, Python, JavaScript, TypeScript, or Node.js., * Experience securing retail, ecommerce, payments, loyalty, customer identity, fraud prevention, or high-traffic customer-facing platforms built on modern web, cloud, container, CDN, or edge architectures. * Experience with application security and delivery platforms. * Experience improving AppSec outcomes through automation, prototypes, AI security practices, secure AI-assisted development, model/component inventory, or developer remediation workflows., * Application Security Scanning: SAST, DAST, SCA * Containerization and CI/CD Toolsets * Public Cloud Security: AWS, GCP, Azure, Oracle Cloud * Web Application Security: Web Application Firewalls (WAF), Runtime Application Self-Protection (RASP), Bot Identification and Prevention * Languages: Java, python, node.js and/or other popular languages EDUCATION/LICENSING/CERTIFICATIONS: * Graduation from an accredited institution with a Bachelor's degree in Engineering, Information Systems, Computer Science or a related field or any combination of education and/or experience. * OSCP * SANS/GIAC (GWAPT, GSEC, GCIH, GCIA, etc.) * Public Cloud DevOps certifications * CEH * Relevant coding certifications, This position requires you to sit, stand and perform general office functions. You may also be required to lift up to 25 pounds occasionally. Bending, stooping and reaching are also frequently required. ## Description * Lead the Application Security team across secure SDLC enablement, vulnerability management, secure code review, security testing, and developer partnership. * Oversee application security reviews, including architecture and design review, threat modeling, code review, API security review, and targeted testing. * Own application vulnerability governance, including intake, triage, prioritization, SLA management, remediation tracking, validation, exceptions, and leadership reporting. * Manage vulnerability disclosure, bug bounty, and external findings processes. * Partner with CI/CD, DevOps, SRE, Platform Engineering, and development teams to integrate security controls into delivery pipelines. * Translate security findings into actionable remediation plans and maintain application security requirements and control expectations aligned to internal standards and industry practices. * Drive secure design and remediation for commerce platforms, APIs, web applications, mobile-supporting services, cloud workloads. * Identify and reduce software supply chain risk, including vulnerable or malicious packages, dependency management gaps, SBOM visibility, repository controls, and dependency confusion risks. * Support application-related security incidents and postmortems. * Partner with Security Operations on WAF, bot mitigation, cloud security, logging, alerting, and compensating controls when remediation requires staged mitigation or fast-follow delivery. * Create metrics and dashboards showing application security posture. * Deliver developer enablement through application security training, security champion content, secure coding guidance, and just-in-time coaching. * Evaluate application security tooling, vendor capabilities, proof-of-concepts, renewals, and integrations that improve outcomes without unnecessary operational friction. * Contribute to security reviews of AI-enabled development workflows, AI-native application components, model integrations, and emerging secure AI-SDLC practices. * Perform other job-related duties as assigned., * The Application Security Manager is a key role in reducing application risk across Bed Bath & Beyond's technology environment. This position drives the execution of secure SDLC practices, improves remediation discipline, matures developer-facing security capabilities, and ensures application security risks are visible, prioritized, and addressed through defensible governance. The manager grows the capability of the Application Security team while serving as a trusted advisor to engineering and product leaders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)